plugin

Thrive Visual Editor Vulnerabilities

2 known security issues reported for the Thrive Visual Editor WordPress plugin. Most recent disclosed Aug 4, 2026.

1 high 1 medium

Running Thrive Visual Editor on your site? Check whether your installed version is affected.

Scan your site free

Thrive Visual Editor <= 10.9.3.1 - Unauthenticated Stored Cross-Site Scripting

high

The Thrive Visual Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.9.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use...

CVSS:
7.2
Affected:
up to 10.9.3.1
Fixed in:
10.9.3.2
Disclosed:
Aug 4, 2026

CVE-2026-66694 on NVD →

Multiple Thrive Themes and Plugins (Various Versions) - Arbitrary Options Update

medium

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive A...

CVSS:
5.3
Affected:
up to 2.6.7.4
Fixed in:
2.6.7.4
Disclosed:
Apr 23, 2021

CVE-2021-24219 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database